Vulnerability GHSA-9xm2-gw56-wj7m

Medium Risk
MEDIUM RISK
CVSS Score: 6.8
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 months ago
June 23, 2026 at 03:32 PM UTC
OpenShift Cluster Logging Operator missing authorization flaw
<0.0.0-20260804174055-1864c2a9851d
<0.0.0-20260804174055-1864c2a9851d

Summary

OpenShift Cluster Logging Operator missing authorization flaw

Details

A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards ServiceAccount tokens to output destinations without verifying that the ClusterLogForwarder creator has permission to use those credentials, allowing a delegated editor to exfiltrate SA tokens and escalate privileges.

Timeline

Published
3 months ago
June 23, 2026 at 03:32 PM UTC
Last Modified
3 days ago
September 24, 2026 at 07:15 PM UTC